VDB
Sign up
—

PYSEC-2026-808

Fabric vulnerable to symlink attack on tmp files

Quick fix

PYSEC-2026-808 — fabric: upgrade to the fixed version with the command below.

pip install --upgrade 'fabric>=1.1.0'

Details

Fabric before 1.1.0 allows local users to overwrite arbitrary files via a symlink attack on (1) a `/tmp/fab.*.tar` file or (2) certain other files in the top level of `/tmp/`.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/fabric
Introduced in: 0Fixed in: 1.1.0
Fixpip install --upgrade 'fabric>=1.1.0'

References